Live data from Hacker News

The Resolv hack: How one compromised key printed $23M

chainalysis.com

111–120 of 174 posts

Re: The Resolv hack: How one compromised key printed $23M

#111
post #10

If the admins can "lock all transactions", what's the point of it being a crypto?

Exactly. Stablecoins make zero sense.

Unbacked stablecoins like USR make no sense - but USDC is one of the few real uses that crypto has.

Re: The Resolv hack: How one compromised key printed $23M

#112
post #110

Earlier quoted context omitted.

> took a private key from KMS They used KMS to sign the minting operation, but they didn't "take" the key, AWS KMS doesn't let you extract keys.

^ this is a common security misconception in crypto. "We're using an HSM, they can't steal our private key." OK genius now you still have to secure the HSM. There's no shortcut to MPC/multisig with 3+ keyholders.

It's still significantly better, since access can be revoked, vs a leaked key where you're permanently fucked

Re: The Resolv hack: How one compromised key printed $23M

#113
post #110

Earlier quoted context omitted.

> took a private key from KMS They used KMS to sign the minting operation, but they didn't "take" the key, AWS KMS doesn't let you extract keys.

^ this is a common security misconception in crypto. "We're using an HSM, they can't steal our private key." OK genius now you still have to secure the HSM. There's no shortcut to MPC/multisig with 3+ keyholders.

> you still have to secure the HSM

Obviously.

> There's no shortcut to MPC/multisig with 3+ keyholders.

The whole concept of a stablecoin seems to be based on centralised trust. Ultimately there is some org that has the fiat bank account, that mints and redeems the coins.

Re: The Resolv hack: How one compromised key printed $23M

#114
post #24

Earlier quoted context omitted.

Not really. At a traditional bank I have to trust n people with varying degrees of access. Et ceteris paribus, any reduction in n is an improvement, even if n is not zero. Of course n can be smaller and the specific people less trustworthy, but that's quite a different thing.

At a traditional bank you have your national deposit insurance scheme; you get that in return for converting your "assets" to the said nations issued currency but accept the authorities control of the money supply and your funds. With decentralised money, you get the safety of a globally distributed attestation backed by cryptography without a single authority controlling the supply of money or your funds. There is n…

I mean you're just making bare assertions, of course there are halfway options. Different components of the account or relationship can have different parameters. Most crypto products are not the equivalent of depositor accounts anyway, they wouldn't be insured necessarily at a traditional bank either.

Re: The Resolv hack: How one compromised key printed $23M

#115
post #111

Earlier quoted context omitted.

Exactly. Stablecoins make zero sense.

Unbacked stablecoins like USR make no sense - but USDC is one of the few real uses that crypto has.

Decentralized. Stable. Pick one.

Re: The Resolv hack: How one compromised key printed $23M

#116
post #25

What is the point of stable coins? Like why does anyone buy them? It seems to me that their initial value is 1usd per token (or some other fiat I guess) and that's also the roof of their value: they kinda guarantee that they won't become more valuable than that. They are less usable than fiat: more businesses accept fiat than crypto, especially weird and small coins like all stable coins are. There isn't really a flo…

Why have cash? A: as an intermediary between better uses of money (buy cool stuff or invest)

So why use stablecoins and not use cash? When you want to quickly convert to/from a token (60 second not 6 days), but for a short period have a stable value. Or you want to avoid banks.

I.e. trading, gambling, drug deals, money laundering, etc.

Re: The Resolv hack: How one compromised key printed $23M

#117
post #80

Earlier quoted context omitted.

One of the two is very close to something that actually happened to me. I tried to open up a bank account for paying immigration related costs to a particular shithole country, which is both legal and was part of a fully legal endeavor, but no bank would do it. The other example is somewhat concocted but rooted in the time I spent in Iraq and noting almost all transactions are performed outside the banking system, in…

Clearly your situation of trying to obtain residency in the Comoros by investment would raise eyebrows at banks whose job it is to monitor tax compliance. I don't think you're describing an everyman kind of scenario. I also don't entirely understand why you're even rationalising the purpose of the account to the bank. Can't you just open an account for any purpose? It takes me five minutes to open an account online,…

> You realise you can walk into any US bank right now and they'll just open an account for you with nothing more than some accurate ID?

There's an ocean in the way, not to mention how risky visiting looks right now. I changed my name recently and the one US bank that I managed to get an account with (so that US clients can pay me without weirdness) won't accept any kind of documentation without going there in person (and I'm not sure I can provide anything they'll accept even if I did go there in person). What now?

Re: The Resolv hack: How one compromised key printed $23M

#118
post #95

Earlier quoted context omitted.

Stablecoins present less frictions, have cheaper transaction costs and less intermediaries susceptible to block them. It greatly increases the velocity of money.

What utterly horrendous payment solutions are you using that have more friction than crypto? The ones I use are several orders of magnitude less friction and most are 100% free. The ones that do have a cost (for recipients outside Scandinavia basically) are still way, waay cheaper than crypto transactions.

How do you have a payment system that is free? Who pays for the infrastructure?

Re: The Resolv hack: How one compromised key printed $23M

#119

Earlier quoted context omitted.

Exactly. Stablecoins make zero sense.

Stablecoins enable cash-like (instantly redeemable and verifiable) payments for large amounts, for almost free. In EU countries, you can't now buy a car with cash. You have to buy a bearer's check from your bank, which is expensive, requires that both parties have a brick and mortar bank, and doesn't work cross-border. Stablecoins solve this.

It was good while ago, but last time I bought a car I just did bank transfer. SEPA transfers are entirely free. Was kinda amazed that they just handed me keys when I showed them the receipt from my own online bank...

Re: The Resolv hack: How one compromised key printed $23M

#120
post #19

Earlier quoted context omitted.

Yeah, people who genuinely believe that don't have any problem with smart contracts getting exploited. Of course there are people who _say_ that because it's financially expedient at the time, then change their tune. But both groups exist and this is not really a gotcha.

I dont mind smart contracts getting battle tested. I also dont mind the whole chain coming together to vote to reverse the transaction. I also dont mind a bunch of people being unhappy with that and forking.

That's fine. I just see it as heuristics at different levels. In the wider context, generally, markets work well, so people should be 'allowed' to do all of this. After all, you can choose not to use ETH if you think the foundation sucks. Whether ETH or the foundation sucks is a technical question given your goals, I suppose, rather than a moral one.

In a western legal framework you might argue promissory estoppel if the foundation made certain statements about it, but if you take the libertarian code-is-law stance and you want to be consistent then you probably should have researched exactly what was possible at that level before investing.

So all-in-all, seems fine to me.

Post reply on HN